Malicious code in an image could enter PC through browser
Malicious code in an image could enter PC through browser
R E L A T E D   C O N T E N T
ADVERTISEMENT

Mozilla fixes new Firefox flaw

Users urged to download patched version immediately

Iain Thomson, vnunet.com 24 Mar 2005
ADVERTISEMENT

The Mozilla Foundation has released a new security patch for its Firefox internet browser and is urging users to install it.

The patch fixes a flaw in the software that handles animated GIF images that could cause a buffer overflow.

If a hacker embedded malicious code in an image it could conceivably enter a PC through the browser software, although no exploit code has yet been found in the wild.

"The Mozilla Foundation is deeply committed to providing its users with the safest internet experience possible," said Chris Hofmann, director of engineering at Mozilla.

"To deliver our users the experience they deserve, we must stay ahead of the curve in patching potential vulnerabilities. For example, the bug patched in this update has no known real world exploits, and we were able to provide a quick response."

The flaw came to light after work done by security researchers at Internet Security Systems but was fixed before they published their report. This is the second Firefox patch to be released in the past month. The buffer overflow patch is available here.

See also:

Users advised to diasable JavaScript in Firefox browserHoles could allow hackers to implant Trojan or key-logger  09 May 2005
'Use another product,' advises browser firm  28 Apr 2005
Incentives for users to identify flaws in Mozilla softwareUsers who find flaws offered $500 per bug plus a free T-shirt  31 Mar 2005
Global usage share nears nine per centIE5 users might be moving to Firefox not IE6, says web analytics firm  01 Mar 2005
Firefox market share gains slow to 15 per centStellar growth of open source browser begins to slow  28 Feb 2005
25 million downloads since NovemberOpen source browser making its way into the mainstream  22 Feb 2005

All Ecommerce

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | The Crown Estate
 EDM Administrator - London - £22,300 to £24,200pa The Crown Estate is a unique organisation that manages a vast and varied property portfolio, comprising commercial, agricultural and marine interests throughout Britain. We are looking for an ... more >
London, United Kingdom | City of London
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
Reading, Berkshire, United Kingdom | EDS
Technical Hosting Engineer Location - Reading Job Description: This is an applications infrastructure and engineering role within the team. This role is primarily focussed on developing and evolving a quarantine application hosting service. The quarantine ... more >
Central London, United Kingdom | MI5 Security Service
Communications Centre Engineer - Competitive salaries + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to ... more >
More job opportunities